Impact
Oracle Contracts, part of Oracle E‑Business Suite, contains a vulnerability in the Internal Operations component. The flaw allows an attacker that already has high‑level privileges and can reach the system over HTTP to fully compromise the application. The weakness is an access control issue (CWE‑269) which invalidates the confidentiality, integrity and availability of Oracle Contracts, effectively granting the attacker full control and the ability to perform any action the legitimate privileged user could.
Affected Systems
Affected product: Oracle Contracts for Oracle E‑Business Suite, version 12.2.14 through 12.2.15. Vendor: Oracle Corporation.
Risk and Exploitability
The assessed CVSS score is 7.2, indicating high severity. The EPSS score of less than 1% suggests limited exploitation activity in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The exploit requires the attacker to have high privileges and network access via HTTP. Attackers could remotely call the vulnerable internal operations interface to achieve full control of Oracle Contracts.
OpenCVE Enrichment